PT-2026-91592 · Apple · Visionos+7

CVE-2026-84530

·

Published

2026-05-19

·

Updated

2026-09-22

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions iOS versions prior to 26.7 iPadOS versions prior to 26.7 macOS Golden Gate versions prior to 27 macOS Tahoe versions prior to 26.7 tvOS versions prior to 27 visionOS versions prior to 27 watchOS versions prior to 27
Description An information disclosure issue exists where an application can disclose kernel memory. Specifically, a kernel address leak occurs in the AIO (Asynchronous I/O) subsystem. The aio register kevent function places an aio workq entry pointer into kqueue metadata. This pointer is subsequently copied into kn sdata by kevent register and stored in kn hook by filt aioattach, but it is never cleared from kn sdata. Consequently, userspace can read this leftover kernel pointer via kqext sdata.
Recommendations Update iOS to version 26.7 or later. Update iPadOS to version 26.7 or later. Update macOS Golden Gate to version 27 or later. Update macOS Tahoe to version 26.7 or later. Update tvOS to version 27 or later. Update visionOS to version 27 or later. Update watchOS to version 27 or later.

Fix

DoS

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07470
CVE-2026-84530

Affected Products

Apple Macos
Ios
Ipados
Macos Golden Gate
Macos Tahoe
Tvos
Visionos
Watchos